fix: bump golang.org/x/net + x/text (Aikido, qor5 team 296964) - #1100
Merged
dorothyyzh merged 1 commit intoJul 27, 2026
Conversation
- golang.org/x/net v0.55.0 -> v0.56.0 (CVE-2026-46600, out-of-bounds read) - golang.org/x/text v0.38.0 -> v0.39.0 (CVE-2026-56852, DoS infinite loop) - go mod tidy passes; go build verified minus the pre-existing local bimg/libvips cgo dep (needs pkg-config/libvips, absent in this sandbox) -- unrelated to this change, builds in CI. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Go | Jul 24, 2026 10:14a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
Codecov Report✅ All modified and coverable lines are covered by tests. 🚀 New features to boost your workflow:
|
iBakuman
approved these changes
Jul 24, 2026
dorothyyzh
added a commit
that referenced
this pull request
Jul 27, 2026
…-xrtk Resolve go.mod conflict: keep grpc v1.82.1 + genproto rpc and x/oauth2 v0.36.0 from this branch; x/net v0.56.0 and x/text v0.39.0 already landed on main via #1100. go mod tidy clean.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves the Aikido High
golang.org/x/*findings for qor5/admin (team 296964).golang.org/x/netv0.55.0 → v0.56.0 (CVE-2026-46600, out-of-bounds read)golang.org/x/textv0.38.0 → v0.39.0 (CVE-2026-56852, DoS via infinite loop)Verification
go mod tidyclean.go build ./...verified except the pre-existinggithub.com/theplant/bimgcgo dependency (requires libvips/pkg-config, not installed locally) — unrelated to this change; builds in CI.Note
Separate from the existing Aikido AI-Fix grpc PR (#1099) — different finding; both can merge independently.
Skill does not touch
release-*branches; merging/promoting is per team policy.